All incidents

AliExpress audio fingerprinting disrupts Bluetooth headset use

incidentopenAug 23, 2026 — Aug 24, 2026
AliExpress’ inaudible sound trick disrupts Bluetooth headset

ALIEXPRESS has been caught using an inaudible sound technique that interferes with Bluetooth headsets, a practice uncovered by independent researcher Matthew Callaghan. The method sends silent audio signals through browsers to create a device fingerprint while disrupting wireless audio devices. This raises immediate privacy and usability concerns for shoppers on the site.

The attack relies on two heavily obfuscated JavaScript files named collina.js and fireyejs.js, which generate silent WebAudio contexts as soon as the AliExpress homepage loads. These contexts probe the audio subsystem, capturing nuances of the sound hardware and combining them with canvas rendering and other browser attributes to build a unique identifier. Although the audio is below human hearing, it keeps the Bluetooth audio channel busy, causing headsets to disconnect or stutter.

No CVE identifiers have been assigned because the behaviour stems from a website design choice rather than a software vulnerability. The fingerprinting script runs without user consent and is hidden within the page’s resource collection, making it difficult for casual visitors to detect. Researchers note that the technique is an evolution of older audio‑based fingerprinting methods that browsers have begun to mitigate.

While Firefox and Chrome have introduced restrictions that limit unauthorized audio context creation, AliExpress appears to have retained additional fingerprinting vectors, including canvas and WebGL probes, to maintain tracking capability. There is no evidence linking this activity to any known threat actor, and the site maintains that the data helps fight fraud. Nonetheless, the combination of covert audio signals and persistent tracking has alarmed privacy advocates.

The issue was first observed when users reported their Bluetooth headphones cutting out shortly after opening the AliExpress homepage, prompting Callaghan’s investigation. Since the initial report, the researcher has published proof‑of‑concept code showing how the scripts can be blocked, and the finding has been covered by Ars Technica and SecurityOnline, highlighting the broader implications for online tracking.

Users should consider installing content‑blocking extensions such as uBlock Origin and adding filters that target the collina.js and fireyejs.js domains, which can stop the silent audio contexts from being spawned. Keeping browsers up to date ensures that the latest anti‑fingerprinting mitigations are applied, reducing the chance of unintended audio access.

Additional steps include reviewing site permissions to block audio capture unless explicitly trusted, using a separate browser profile for shopping to isolate potential tracking, and monitoring Bluetooth device logs for unexpected disconnections that may signal abusive scripts. Staying vigilant about unexpected behaviour remains the most effective defence against covert fingerprinting techniques.

Intelligence briefing updated Aug 24, 2026

Root sourceblog.laserphile.com
Timeline Coverage

Swipe to explore timeline